Weekly cloud scan
486/492700+ automated checks
Cloud, code, and identity scans run on schedule across 60+ providers and map to controls.
One MFA scan satisfies SOC 2 and HIPAA at once.
An AI compliance officer, not another dashboard
Reach an auditor-ready SOC 2 or HIPAA in weeks, for $499/month. No compliance hire, no consultants, no prior experience.
Evidence
70%
Collected automatically
Providers
60+
Native integrations
Checks
700+
Automated evidence checks
Founder effort
<10 hrs
Not 80+ hours
Measured across SOC 2 Type I engagements on the current control catalog
Scans the systems you already run
AWS
Google Cloud
Azure
Google Workspace
1Password
CrowdStrike
Wiz
Tailscale
AWS
Google Cloud
Azure
Google Workspace
1Password
CrowdStrike
Wiz
TailscaleWhat else is in the box
Trust Center, vendor management, and questionnaire answering are usually three more line items on the invoice.
Here they are, in the same price.
Weekly cloud scan
486/492Cloud, code, and identity scans run on schedule across 60+ providers and map to controls.
One MFA scan satisfies SOC 2 and HIPAA at once.
Annual security training
42/48Onboarding, annual training, and policy acknowledgments tracked per employee.
Chase nobody. Vera sends the reminders.
Managed endpoints
62Laptops, cloud resources, and SaaS accounts with owners, encryption, and MDM state.
Every asset accounted for, without a spreadsheet.
Q2 access review · prod
2 to revokeVera pulls the entitlement list, routes it for approval, and files the result.
The review that everyone forgets, on a schedule.
trust.acme.com · public
LiveA public page with your certifications, policies, and subprocessors, built from live evidence.
Prospects stop emailing you for the SOC 2 report.
Third-party register
Third-party risk management: every vendor tracked with risk tier, DPA status, and their SOC 2 report.
Included, not a $12K add-on line item.
Q: Do you encrypt customer data at rest?
Yes. AES-256 on all RDS instances and S3 buckets.
Also answered
Answers drafted from your actual controls, with the control ID attached.
Every answer traces back to evidence you can show.
Risk register
5 over appetiteA live register with inherent and residual scoring, owners, and treatment plans.
The risk assessment your auditor asks for on day one.
Vera assembles structured context from GitHub, AWS or GCP, your IdP, and existing evidence before a single policy is written. The overpromise checker flags hard commitments unsupported by what she found, before your auditor does.
No policy makes a promise your systems can't keep.
Acme Corp enforces multi-factor authentication through Okta for all administrative access to production systems. verified
Production access is reviewed quarterly by the security team to remove stale entitlements. overpromise
Vera flagged this claim
No quarterly access review evidence found in the last 12 months across Okta and GitHub. Soften to "periodic reviews as needed", or commit to quarterly and let me schedule them.
70% of evidence is collected automatically across 60+ providers and 700+ checks. Vera posts a readiness briefing in Slack at 6:30 AM, delegates the rest by DM, and ingests files dropped right back at her, zero dashboard uploads.
Compliance happens in the channel your team already reads.
compliance
8 members · pinned: SOC 2 program
Daily compliance briefing · Mon Apr 28
Weekly cloud scan · 500 checks
Vanta and Drata link evidence to controls, that's it. Screenata links a specific sentence in a policy to a testable claim, to the control test that verifies it, to a cryptographically signed artifact your auditor can verify outside Screenata.
Your auditor can check the proof without taking our word for it.
Policy sentence
Administrative access requires MFA through Okta.
Access Control Policy / §3.2
Policy claim
MFA enforced for admin accounts
CC6.1 · IA-2 · IMPLEMENTED
Control test
Okta MFA policy verification
Native API check · 24h freshness
Evidence artifact
Signed Okta API response
SHA-256 + RFC 3161 timestamp
The enterprise API, screenata CLI, GitHub App, and MCP server are one architecture. Every tool hits the same API. Compliance-as-code, not yet another tab.
Nobody has to open the dashboard.
$
What auditors need first
“Until we have all the policies in place, the risk assessment completed, system description completed, a timestamped network diagram, a vulnerability scan report, we wouldn’t be able to begin with control testing.”
SOC 2 auditor
Screenata delivers all 8 of those artifacts, policies, risk assessment, system description, network diagram, org chart, control matrix, vulnerability review, and oversight minutes, in 4–6 weeks, before your observation window opens.
Architecture, not adjectives
Cloud provider keys live in Azure Key Vault, retrieved at scan time, never cached or logged.
A breach of us is not a breach of you.
No write scopes on your repos or cloud. Source code is scanned in memory and never persisted.
We cannot change your infrastructure, by design.
RSA/ECDSA signatures, RFC 3161 timestamps, SHA-256 manifests, BYOK. Open spec + free verify CLI.
Check the proof without an account.
What it actually costs
You are not paying for a dashboard. You are paying for the work.
Run a compliance practice? Resell or refer Screenata to your clients, Vera does the operational grind, you keep the advisory relationship.
Partner with usFAQ
Vanta and Drata are dashboards a human compliance person works inside. Screenata is the compliance person. Vera scans your infrastructure, writes policies from what's real, collects evidence, runs scheduled checks at 6 AM, and delivers everything through Slack, email, GitHub, and your terminal. The dashboard exists for auditors and deep dives, the daily work happens where you already are.
Yes. Daily 6:00 AM evidence freshness checks, daily 6:15 AM readiness snapshots, weekly Monday cloud and code scans, quarterly access reviews, and annual risk refreshes all run on scheduled jobs. Vera flags stale evidence, drafts delegation messages, scopes remediation, and posts agent reports. You approve actions; you don't run them.
Screenata scans first, then writes. We pull context from GitHub, AWS or GCP, your IdP, existing evidence, and your company profile, then generate policies grounded in what we found. The overpromise checker flags hard commitments (like 'quarterly access reviews') we cannot verify in evidence, before you ever ship them to an auditor.
Yes. Each claim in a policy is anchored to a specific sentence and linked to the control test that verifies it. Each test has its evidence submissions, and each submission references a cryptographically signed artifact. An auditor can hover any claim in a policy, see the test that proves it, and verify the evidence package independently with a signed manifest.
Evidence exports are tamper-evident: SHA-256 per-file hashes, RSA or ECDSA digital signatures, RFC 3161 independent timestamps, and BYOK support so enterprises can sign with their own keys. We're publishing the format as an open spec with a free verify CLI so anyone can check a Screenata pack without an account.
Yes, Slack is a first-class surface, not a notification channel. Vera posts daily readiness briefings in your #compliance channel at 6:30 AM, DMs teammates for evidence with step-by-step instructions, and accepts file drops directly in Slack, auto-classifying, signing, and routing them to the right control. Slash commands and approval blocks are built in. The dashboard exists for auditors and deep dives; daily compliance work happens where your team already talks.
Yes. Every artifact is mapped to specific Trust Services Criteria or HIPAA safeguards, signed with SHA-256 + RFC 3161 timestamps, and traceable from policy claim → control test → submission → vault artifact. Auditors get a structured pack, not a folder of screenshots, and can verify integrity independently with a free CLI. We design the output for what auditors actually look for in fieldwork: completeness, attribution, freshness, and tamper evidence.
Yes, Screenata is built to make your practice more profitable, not to replace it. vCISO firms resell or refer Screenata to their clients. Vera absorbs the policy writing, evidence chasing, and status reporting that eats 60% of your hours, so you can take on 3x the clients at the same headcount while keeping the advisory relationship and the margin. You get a firm-admin account across your client tenants. See screenata.com/for-vcisos for the partner program.
SOC 2 and HIPAA today, with more on the way. Our control model uses a shared canonical catalog so a single MFA scan satisfies SOC 2 CC6.1 and HIPAA §164.312(d) at the same time, and the same scan will map to ISO 27001 and other frameworks as we add them. You collect evidence once instead of paying for each framework separately.
Connect and see
Connect GitHub and cloud read-only. Vera shows your control matrix, policy gaps, stale evidence, and prioritized next actions before you commit to anything.